KairosAI
BackBack to home
LEGAL

Data Processing Addendum

KairosAI Technologies Private Limited · Last updated 22 July 2026 · Effective date: 30 June 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between KairosAI Technologies Private Limited (“KairosAI”, “we”, “us”), a company incorporated under the Companies Act, 2013 and having its registered office at Flat No. E-506, Pristine Allure, S.No. 20/2A, Vadgaon Sheri, Pune City, Pune, 411014, Maharashtra, India and the Customer (“you”) for use of the hosted KairosAI dashboard and AI workforce platform: AI agents that handle conversations across voice (including PSTN telephony), WhatsApp, Instagram, email and web chat on behalf of businesses, together with built-in business tools including a lightweight CRM, quoting and invoicing, payroll and a people directory (the “Service”). It governs KairosAI’s processing of personal data on your behalf and is aligned with India’s Digital Personal Data Protection Act, 2023 (the “DPDPA”) and the Information Technology Act, 2000. In the event of conflict on data-protection matters, this DPA prevails over the Terms & Conditions.

1. Definitions

Terms below take the meaning given in the DPDPA:

  • Data Fiduciary: the person who, alone or with others, determines the purpose and means of processing personal data. You are the Data Fiduciary.
  • Data Processor: a person who processes personal data on behalf of a Data Fiduciary. KairosAI is the Data Processor.
  • Data Principal: the individual to whom the personal data relates (for example, your end-users and the callers, contacts and visitors who interact with your agents).
  • Personal Data: any data about an individual who is identifiable by or in relation to such data.
  • Sub-processor: a third party engaged by KairosAI to process personal data in connection with the Service.

2. Scope & roles

This DPA applies to the processing of personal data contained in the conversation content and related data handled through the Service (such as voice recordings, call transcripts, WhatsApp, Instagram and web-chat messages, email contents and contact identifiers such as phone numbers and email addresses). You determine the purposes and means of processing; KairosAI processes such personal data solely as the Data Processor to provide the Service. You are responsible for the lawfulness of the data and for issuing all required notices and obtaining all consents from Data Principals under the DPDPA, including for any voice or messaging outreach subject to TRAI / DLT regulations.

3. Processing on documented instructions

KairosAI will process personal data only on your documented instructions, including as set out in the Terms & Conditions, this DPA and your configuration of the Service, except where otherwise required by applicable law (in which case we will inform you unless legally prohibited). We will not process the personal data for our own independent purposes and will not sell personal data.

4. Confidentiality

KairosAI will ensure that personnel authorised to process the personal data are bound by appropriate confidentiality obligations and access the data only on a need-to-know basis. Multi-tenant isolation is enforced by carrying a tenant identifier on every record and scoping every request to a single tenant at the application layer, with automated cross-tenant tests in our build pipeline. Underneath that, PostgreSQL row-level security is enforced at the database on a least-privilege role that cannot bypass it, so a query without a tenant context returns no rows; see our Security Overview.

5. Security measures

KairosAI will implement and maintain reasonable technical and organisational security safeguards appropriate to the risk, including encryption of personal data in transit (TLS) and at rest, AES-GCM encryption and storage of secrets in a managed secrets store, role-based access controls, application-layer tenant scoping with automated cross-tenant tests, network and perimeter controls including a web application firewall at the edge, a tamper-evident hash-chained audit log of administrative write actions, operational monitoring, regular backups and regular review of controls. These measures are consistent with the DPDPA’s requirement to protect personal data in our possession or under our control and with reasonable security practices under the Information Technology Act, 2000.

Some controls that a Customer may expect are not yet in place, including multi-factor authentication and alerting on intrusion-detection findings, and no third-party penetration test has been carried out. Our Security Overview lists the current status of each control under development and is kept up to date as that status changes.

6. Sub-processing

You authorise KairosAI to engage sub-processors to provide the Service. KairosAI will impose data-protection and confidentiality obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance. We will maintain the list below and give you a reasonable opportunity to object to material changes to sub-processors.

We engage sub-processors in the categories below. We name the categories, their purpose and their processing location rather than specific vendors; the current named list is available to Customers on request and on reasonable notice of material changes.

Categories of sub-processors engaged by KairosAI
CategoryPurposeLocation
Cloud / hosting & storageApplication hosting, compute, database & object storageIndia (Mumbai)
LLM providerLarge-language-model response generationCross-region inference
Transactional emailOutbound transactional & agent email deliveryIndia (Mumbai)
Telephony / PSTNVoice call origination & terminationIndia
Realtime voice transportRealtime audio media transport for live voice agentsVendor cloud; serving region not pinned in our code
Messaging / WhatsApp & InstagramWhatsApp template & conversation and Instagram DM deliveryUnited States
PaymentsPayment processing, mandates & wallet rechargeIndia
Speech-to-text / text-to-speechSpeech recognition & speech synthesis; receives raw call audio and the resulting transcriptsVendor hosted API; processing region not pinned in our code
Document AI / OCRText and expense extraction from uploaded documentsIndia (Mumbai)
LLM observabilityTracing of model prompts and completions for debugging and quality reviewEuropean Union; disabled by default
Product analyticsDashboard product-usage analyticsEuropean Union

7. Assistance with Data Principal requests

Taking into account the nature of the processing, KairosAI will provide reasonable assistance through appropriate technical and organisational measures to help you respond to requests by Data Principals to exercise their rights under the DPDPA (access, correction, completion, updating, erasure, grievance redressal and nomination). Where a Data Principal contacts KairosAI directly, we will refer the request to you as the Data Fiduciary.

8. Personal data breach notification

KairosAI will notify you without undue delay and in any case within seventy-two (72) hours of becoming aware of a personal data breach affecting personal data processed under this DPA and will provide information reasonably available to help you meet your obligations to Data Principals and to the Data Protection Board of India under the DPDPA. Breach notifications will be sent to your registered account contact and may also be raised with you at hello@trykairos.in.

9. Deletion or return on termination

On termination or expiry of the Service, or on your written request, KairosAI will delete or return the personal data processed under this DPA. Deletion happens in tiers:

  • Active production systems (databases, object storage and search indexes serving the Service): the account is deactivated immediately and the data is then permanently destroyed after a thirty (30) day grace window in which the account can still be restored on your request.
  • Encrypted backups and database snapshots: not selectively edited. They age out and are destroyed on their ordinary retention schedule, after which no copy remains. Until then the data stays encrypted, is not used to provide the Service and is restored only for disaster recovery.
  • Statutory carve-out: data we are required by law to retain is kept for the period required and then deleted.

We will confirm deletion on request. Default retention windows and your configurable retention settings are described in the Service. Note that prepaid wallet balances, metered usage records (voice minutes, messages) and tax records may be retained as required for accounting and statutory purposes.

10. Audit

On reasonable prior written notice and no more than once per year (or following a confirmed breach), KairosAI will make available information reasonably necessary to demonstrate compliance with this DPA, which may take the form of third-party audit reports, certifications, or a completed questionnaire, subject to confidentiality and to not compromising the security of other Customers.

11. Cross-border transfer

The Service is primarily hosted on cloud infrastructure in India (Mumbai region). Where KairosAI transfers personal data outside India through a sub-processor (as identified in the category table above), it will do so in accordance with the DPDPA and any restrictions notified by the Central Government, under appropriate contractual safeguards with the recipient.

12. Fees & taxes

Fees for the Service are billed through a prepaid wallet in INR, from which metered usage (such as voice minutes and messages) is debited, as described in the Terms & Conditions. All fees are exclusive of applicable taxes. KairosAI is not currently registered for Goods and Services Tax (GST); if and when KairosAI becomes GST-registered, GST will be charged at the applicable rate and valid tax invoices will be issued.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions, to the maximum extent permitted by law, including the Consumer Protection Act, 2019 where applicable.

14. Governing law & dispute resolution

This DPA is governed by the laws of India. The courts at Pune, Maharashtra have exclusive jurisdiction over any dispute arising out of or in connection with this DPA. Any arbitration shall be seated at Pune, Maharashtra, conducted in English, under the Arbitration and Conciliation Act, 1996.

15. Contact

Data-protection questions under this DPA and all support, legal, privacy, grievance and security matters, can be sent to hello@trykairos.in. Our Grievance / Contact Officer under the DPDPA is Vishal Khandelwal, Founder, reachable at grievance@trykairos.in. KairosAI Technologies Private Limited, Flat No. E-506, Pristine Allure, S.No. 20/2A, Vadgaon Sheri, Pune City, Pune, 411014, Maharashtra, India. See also our Privacy Policy.

Terms of ServicePrivacy PolicyRefund & CancellationShipping & ExchangeCookie PolicyAcceptable UseSecurityData Processing AddendumContact
KairosAI

AI that runs the business, not just the conversation. Voice, WhatsApp, Instagram, web chat and email: one AI workforce, shared memory.

Product
  • Agents
  • How It Works
  • Pricing
  • FAQ
  • Compare
  • Industries
  • Cost Calculator
Industries
  • Real estate
  • Fitness & gyms
  • Coaching & edtech
  • Clinics & healthcare
  • Salons & beauty
  • Ecommerce
  • D2C brands
  • Fintech
  • Travel & hospitality
  • Automotive
Company
  • Docs
  • Careers
  • Contact Us
  • Contact Sales
  • Status
Legal
  • Terms of Service
  • Privacy Policy
  • Refund & Cancellation
  • Shipping & Exchange
  • Cookie Policy
  • Acceptable Use
  • Security
  • Data Processing Addendum
© 2026 KairosAI Technologies Private LimitedSystem Status
Recognised byStartup India, DPIIT recognised